Sign inSign up
Socket CLI

dhi.io/socket-cli

Socket CLI 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.1-debian-fips-dev, 1.1-debian13-fips-dev, 1.1-fips-dev, 1.1.176-debian-fips-dev, 1.1.176-debian13-fips-dev, 1.1.176-fips-dev

Index digest:

sha256:9fc5d5dba840ed6bf7f2113f6ebffa30f1623628309460ace0249843e4bd547e

Manifest digest:

sha256:57c31d79d064b9f7bcc5f1b9e89bdaeccb5d307c1366ec733046cd321cc5c7dd

Size

84.38 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
2
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/socket-cli:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/socket-cli:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/socket-cli@sha256:094b3b8adddcd0a8e25b8eed865ba125f8328a82fb8ff9b8637305a625cde6a3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/socket-cli@sha256:28171f1135bfaf164dc1b081db77ddcc18ef11fe5115913eea6623a0f3cf1474
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/socket-cli@sha256:dfff31ae4fced4f7fadfd51f55eae2a2ae1a4e0f5732d4e0610f68f79e60dd85
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/socket-cli@sha256:16532b457df90ba3f0a3872d01c7cb005aeb88509c06ea7f81189a293e00a899
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/socket-cli@sha256:ef50cb9c2fc8b6091b389e2a5f35a432ccd3a5e59617c96f8889ac45fb58142f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/socket-cli@sha256:264c81fa172907927e3bd0e7188cc667d2e4b50aa0ca0c8fc38483963772f3f1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/socket-cli@sha256:53a78602dbc0d86a5bcaaab24be3c8b3f57057ba9c12bd718149926ad646e738
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/socket-cli@sha256:d8aa041e08534e9f7cffb6d5560dc7bdffc2da8ad450610be99b20aa037fcfe3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/socket-cli@sha256:dbd9ce0147fb16df98f6a6c266dc2ea183df9fa24d9d0e2d0af4ea3ab8f647f2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/socket-cli@sha256:1455e82b55b853ab26af4c41bb1dcab97111cc46f42e2434e9c59af9c546c934
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/socket-cli@sha256:3af1ab0d903b56f8437ad80ab1ef3c54283afa983b12261144803ad3669047e5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/socket-cli@sha256:a93be66b1188b8f1dc947f46a55fda73d27d88ca1b6687e0c78eebb7932b095f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/socket-cli@sha256:eb8be399e07be5db038b46f0ba509f1cafecc8d115324e9a5d9dd04613c0e5a4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/socket-cli@sha256:d78d874987535fe3ea3fd4c367c295b4f678065b0f855b9121e3bd6e49cbbed9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/socket-cli@sha256:997d1e0abefa645ff8d9e497602e4c5d3f54b88aaf1b02491ccea202d89cb02a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/socket-cli@sha256:1097d8b296d05837e4c7c50b709e410b6e02f6727aec373e33c52f03ff04c47e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/socket-cli@sha256:0a2f5f03a187593077bb2c3799420a4add4d872af64a36bbf8aecfb25638cede